Vulnerabilities > Low

DATE CVE VULNERABILITY TITLE RISK
2015-06-15 CVE-2015-4381 Cross-site Scripting vulnerability in Invoice Project Invoice 6.X1.1/7.X1.Xdev
Cross-site scripting (XSS) vulnerability in the Invoice module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.3 for Drupal allows remote authenticated users with the "Administer own invoices" permission to inject arbitrary web script or HTML via unspecified vectors involving nodes of the "Invoice" content type.
3.5
2015-06-15 CVE-2015-4380 Cross-site Scripting vulnerability in Linear Case Project Linear Case
Cross-site scripting (XSS) vulnerability in the Linear Case module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
3.5
2015-06-15 CVE-2015-4378 Cross-site Scripting vulnerability in Crumbs Project Crumbs 7.X2.0/7.X2.1/7.X2.2
Cross-site scripting (XSS) vulnerability in the Crumbs module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with the "Administer Crumbs" permission to inject arbitrary web script or HTML via a custom breadcrumb separator.
network
high complexity
crumbs-project CWE-79
2.1
2015-06-15 CVE-2015-4377 Cross-site Scripting vulnerability in Petition Project Petition 6.X1.0/6.X1.1/6.X1.2
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Petition module 6.x-1.x before 6.x-1.3 for Drupal allows remote authenticated users with the "create petition" permission to inject arbitrary web script or HTML via unknown vectors.
network
high complexity
petition-project CWE-79
2.1
2015-06-15 CVE-2015-4376 Cross-site Scripting vulnerability in Profile2 Privacy Project Profile2 Privacy
Cross-site scripting (XSS) vulnerability in the Profile2 Privacy module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Profile2 Privacy Levels" permission to inject arbitrary web script or HTML via unspecified vectors.
3.5
2015-06-15 CVE-2015-4373 Cross-site Scripting vulnerability in OG Tabs Project OG Tabs 7.X1.0
Cross-site scripting (XSS) vulnerability in the OG tabs module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to nodes posted in an Organic Groups group.
3.5
2015-06-15 CVE-2015-4372 Cross-site Scripting vulnerability in Image Title Project Image Title 7.X1.0
Cross-site scripting (XSS) vulnerability in the Image Title module before 7.x-1.1 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.
3.5
2015-06-15 CVE-2015-4370 Cross-site Scripting vulnerability in Site Documentation Project Site Documentation
Cross-site scripting (XSS) vulnerability in the Site Documentation module before 6.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors related to taxonomy terms.
3.5
2015-06-15 CVE-2015-4369 Cross-site Scripting vulnerability in Trick Question Project Trick Question
Cross-site scripting (XSS) vulnerability in the Trick Question module before 6.x-1.5 and 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with the "Administer Trick Question" permission to inject arbitrary web script or HTML via unspecified vectors.
3.5
2015-06-15 CVE-2015-4367 Cross-site Scripting vulnerability in Simple Subscription Project Simple Subscription 6.X1.0/7.X1.0
Cross-site scripting (XSS) vulnerability in the Simple Subscription module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users with the "administer blocks" permission to inject arbitrary web script or HTML via vectors related to block content.
3.5